Search CVE reports


Toggle filters

1391 – 1400 of 49124 results

Status is adjusted based on your filters.


CVE-2026-20643

Medium priority
Ignored

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 16.04
webkitgtk Ignored
webkit2gtk Ignored
qtwebkit-source Ignored
qtwebkit-opensource-src Ignored
wpewebkit
Show less packages

CVE-2026-4358

Medium priority
Needs evaluation

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is...

1 affected package

mongodb

Package 16.04
mongodb Needs evaluation
Show less packages

CVE-2026-25936

Medium priority
Needs evaluation

GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a SQL injection. Version 11.0.6 fixes the issue.

1 affected package

glpi

Package 16.04
glpi Needs evaluation
Show less packages

CVE-2026-4148

Medium priority
Needs evaluation

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation pipeline.

1 affected package

mongodb

Package 16.04
mongodb Needs evaluation
Show less packages

CVE-2026-4147

Medium priority
Needs evaluation

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.

1 affected package

mongodb

Package 16.04
mongodb Needs evaluation
Show less packages

CVE-2026-3888

High priority
Fixed

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue...

1 affected package

snapd

Package 16.04
snapd Fixed
Show less packages

CVE-2026-4271

Medium priority
Needs evaluation

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2...

2 affected packages

libsoup2.4, libsoup3

Package 16.04
libsoup2.4 Needs evaluation
libsoup3
Show less packages

CVE-2026-3634

Medium priority
Vulnerable

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequence due to improper input sanitization in...

2 affected packages

libsoup2.4, libsoup3

Package 16.04
libsoup2.4 Vulnerable
libsoup3
Show less packages

CVE-2026-3633

Medium priority
Vulnerable

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary headers and additional request data. This vulnerability, known as CRLF (Carriage...

2 affected packages

libsoup2.4, libsoup3

Package 16.04
libsoup2.4 Vulnerable
libsoup3
Show less packages

CVE-2026-3632

Medium priority
Vulnerable

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly validate hostnames, allowing special characters to be injected into HTTP headers. A...

2 affected packages

libsoup2.4, libsoup3

Package 16.04
libsoup2.4 Vulnerable
libsoup3
Show less packages